<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Blog TechNet Brasil : AD</title><link>http://blogs.technet.com/technetbr/archive/tags/AD/default.aspx</link><description>Tags: AD</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Contornando o Event ID 2886 no Windows Server 2008</title><link>http://blogs.technet.com/technetbr/archive/2009/01/13/contornando-o-event-id-2886-no-windows-server-2008.aspx</link><pubDate>Tue, 13 Jan 2009 14:24:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3181650</guid><dc:creator>lucianopalma</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/technetbr/comments/3181650.aspx</comments><wfw:commentRss>http://blogs.technet.com/technetbr/commentrss.aspx?PostID=3181650</wfw:commentRss><description>&lt;p&gt;Quando concluímos a adição da função de &lt;i&gt;Active Directory Domain Service&lt;/i&gt; em um &lt;i&gt;Windows Server 2008&lt;/i&gt;, encontramos um alerta na console do Server Manager, e ao fazermos um &lt;i&gt;Drill Down&lt;/i&gt; teremos o &lt;b&gt;Event ID 2886&lt;/b&gt;. Este alerta é registrado toda vez que iniciamos/reiniciamos o sistema operacional.&lt;/p&gt;  &lt;p&gt;…   &lt;br /&gt;&lt;i&gt;Log Name: Directory Service     &lt;br /&gt;Source: Microsoft-Windows-ActiveDirectory_DomainService      &lt;br /&gt;Event ID: 2886      &lt;br /&gt;Task Category: LDAP Interface      &lt;br /&gt;Level: Warning      &lt;br /&gt;Description:      &lt;br /&gt;The security of this directory server can be significantly enhanced by configuring the server to reject SASL (Negotiate, Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that are performed on a cleartext (non-SSL/TLS-encrypted) connection. Even if no clients are using such binds, configuring the server to reject them will improve the security of this server.      &lt;br /&gt;&lt;/i&gt;….&lt;/p&gt;  &lt;p&gt;Este alerta ocorre porque o ambiente é &lt;i&gt;by design&lt;/i&gt; projetado para compatibilidade do tráfego LDAP com clientes, serviços, e aplicações que não foram modificadas para o suporte a este recurso. Para configurarmos o ambiente para que este alerta deixe de ser registrado, teremos que realizar duas modificações, usando o &lt;i&gt;Group Policy Management&lt;/i&gt;, na política de grupo &lt;i&gt;Default Domain Controllers Policy&lt;/i&gt;, que é a GPO padrão do domínio. Segue abaixo como as duas entradas deverão estar configuradas:&lt;/p&gt;  &lt;p&gt;Computer Configuration   &lt;br /&gt;=&amp;gt; Policies    &lt;br /&gt;==&amp;gt; Windows Settings    &lt;br /&gt;===&amp;gt; Security Settings    &lt;br /&gt;====&amp;gt; Local Policies    &lt;br /&gt;=====&amp;gt; Security Options&lt;/p&gt;  &lt;p&gt;Domain controller: LDAP server signing requirements = “Require signing”&lt;/p&gt;  &lt;p&gt;Computer Configuration &lt;/p&gt;  &lt;p&gt;=&amp;gt; Policies   &lt;br /&gt;==&amp;gt; Windows Settings    &lt;br /&gt;===&amp;gt; Security Settings    &lt;br /&gt;====&amp;gt; Local Policies    &lt;br /&gt;=====&amp;gt; Security Options&lt;/p&gt;  &lt;p&gt;Network Security: LDAP client signing requirements = “Negotiate signing”&lt;/p&gt;  &lt;p&gt;Salientando, estas mudanças obrigam (escopo de domínio) ou haverá negociação (escopo de rede) que o tráfego LDAP seja assinado. Mudando estes parâmetros poderá ocorrer incompatibilidade em alguns clientes, serviços ou aplicações. Entretanto, modificando estas configurações, ganhamos na segurança do ambiente.&lt;/p&gt;  &lt;p&gt;Para melhor entendimento, recomendo consultar o KB823659 e, testar…&lt;/p&gt;  &lt;p&gt;por &lt;em&gt;&lt;strong&gt;Jonildo Santos&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3181650" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/technetbr/archive/tags/Jonildo/default.aspx">Jonildo</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Dicas/default.aspx">Dicas</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Jonildo+Santos/default.aspx">Jonildo Santos</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Santos/default.aspx">Santos</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/technetbr/archive/tags/AD/default.aspx">AD</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Seguran_E700_a/default.aspx">Segurança</category></item><item><title>O que é FSMO?</title><link>http://blogs.technet.com/technetbr/archive/2008/09/18/o-que-fsmo.aspx</link><pubDate>Thu, 18 Sep 2008 18:58:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3125775</guid><dc:creator>lucianopalma</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/technetbr/comments/3125775.aspx</comments><wfw:commentRss>http://blogs.technet.com/technetbr/commentrss.aspx?PostID=3125775</wfw:commentRss><description>&lt;p&gt;Quem já trabalha com Active Directory diariamente já esta acostumado a lidar com esta “palavrinha” com frequência. No Active Directory o conceito de PDC/BDC não existe mais. Todos os controladores de domínio passam a armazenar uma cópia do diretório que pode ser modificada (Exceto no RODC do Windows Server 2008).&lt;br&gt;O acrônimo FSMO significa Flexible Single Master Operation. Ao todo temos 5 mestres de operações (Operation Master), duas que afetam a floresta como um todo e outras três que afetam um domínio. Essas regras tem por objetivo controlar os conflitos que podem existir no modelo Multi-Master do Active Directory.&lt;/p&gt; &lt;p&gt;&lt;b&gt;Floresta&lt;/b&gt; : são regras que afetam toda uma floresta Windows 2000/2003/2008 e podem ser hospedadas por qualquer controlador de domínio dentro da floresta&lt;/p&gt; &lt;p&gt;As regras da Floresta são :&lt;/p&gt; &lt;p&gt;&lt;b&gt;1. &lt;/b&gt;&lt;b&gt;Schema Master&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;2. &lt;/b&gt;&lt;b&gt;Domain Name Master&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;Domínio&lt;/b&gt; : são regras que afetam apenas um domínio Windows 2000/2003/2008, e podem ser hospedadas por qualquer controlador de domínio dentro do domínio&lt;/p&gt; &lt;p&gt;As regras do Domínio são : &lt;/p&gt; &lt;p&gt;&lt;b&gt;1. &lt;/b&gt;&lt;b&gt;PDC Emulator&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;2. &lt;/b&gt;&lt;b&gt;RID Master&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;3. &lt;/b&gt;&lt;b&gt;InfraStructure Master&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Dica : Para determinhar rapidamente quais são os servidores controladores de domínio que são proprietários (owner) de cada FSMO, com o Support Tools instalado (No Windows Server 2008 o comando NETDOM é nativo e não precisa do Support Tools). Basta digitar :&lt;/p&gt; &lt;p&gt;&lt;b&gt;C:\Program Files\Support Tools\NETDOM QUERY FSMO&lt;/b&gt;. O resultado mostra na primeira coluna as 5 regras e na segunda coluna os DCs responsáveis por gerenciá-los.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/OqueFSMO_B656/clip_image002_2.jpg"&gt;&lt;img style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/OqueFSMO_B656/clip_image002_thumb.jpg" width="244" height="123"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Nos próximos posts detalharei a função de cada uma das FSMOs, e na ausência ou falha delas qual problemas podem ocorrer.&lt;/p&gt; &lt;p&gt;por &lt;strong&gt;&lt;em&gt;Gilson Banin&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3125775" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/technetbr/archive/tags/TechNet/default.aspx">TechNet</category><category domain="http://blogs.technet.com/technetbr/archive/tags/TechNet+Brasil/default.aspx">TechNet Brasil</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Infra-estrtutura/default.aspx">Infra-estrtutura</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Banin/default.aspx">Banin</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Dicas/default.aspx">Dicas</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Gilson+Banin/default.aspx">Gilson Banin</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Gilson/default.aspx">Gilson</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows+Server/default.aspx">Windows Server</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows/default.aspx">Windows</category><category domain="http://blogs.technet.com/technetbr/archive/tags/AD/default.aspx">AD</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Active+Directory/default.aspx">Active Directory</category></item><item><title>Identifique seu Active Directory!</title><link>http://blogs.technet.com/technetbr/archive/2008/09/16/tr-s-03-maneiras-de-identificar-qual-vers-o-do-active-directory-pela-vers-o-do-schema.aspx</link><pubDate>Tue, 16 Sep 2008 16:38:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3124731</guid><dc:creator>lucianopalma</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/technetbr/comments/3124731.aspx</comments><wfw:commentRss>http://blogs.technet.com/technetbr/commentrss.aspx?PostID=3124731</wfw:commentRss><description>&lt;p&gt;Se você quer saber qual a versão do seu Active Directory basta você saber qual versão do Schema. A versão do Schema determina qual a versão do sistema operacional do seu Domain Controller mais atualizado. Esse valor é alterado somente quando a Floresta é preparada através do comando “&lt;b&gt;Adprep /Forestprep&lt;/b&gt;”, largamente utilizado na preparação e atualização de um Domínio do Active Directory de uma versão inferior para uma versão mais atualizada (Por exemplo : Active Directory 2003 R2 para Active Directory 2008).&lt;/p&gt; &lt;h4&gt;O significado das versões&lt;/h4&gt; &lt;p&gt;Podem existir cenários onde há mais do que um Domain Controller com versões de sistema operacional diferentes respondendo pelo mesmo domínio; um executando o Windows 2000 Server e outro Windows Server 2003. Neste caso, apesar de ter um DC Windows 2000 como Domain Controller a versão do schema será 31, que corresponde à versão do Domain Controller com o sistema operacional mais atualizado, neste caso o Windows Server 2003.&lt;/p&gt; &lt;p&gt;A tabela abaixo ilustra os valores do Schema e o sistema operacional relacionado.&lt;/p&gt; &lt;table border="1" cellspacing="0" cellpadding="2" width="518"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td valign="top" width="87"&gt; &lt;p&gt;&lt;b&gt;Versão do Schema&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="428"&gt; &lt;p&gt;&lt;b&gt;Sistema Operacional&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="87"&gt;13&lt;/td&gt; &lt;td valign="top" width="428"&gt; &lt;p&gt;Microsoft Windows 2000&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="87"&gt;30&lt;/td&gt; &lt;td valign="top" width="428"&gt; &lt;p&gt;Microsoft Windows Server 2003 e/ou Windows Server 2003 SP1&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="87"&gt;31&lt;/td&gt; &lt;td valign="top" width="428"&gt; &lt;p&gt;Microsoft Windows Server 2003 R2&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="87"&gt;44&lt;/td&gt; &lt;td valign="top" width="428"&gt; &lt;p&gt;Microsoft Windows Server 2008&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt; &lt;h4&gt;Três maneiras para identificar a versão de seu AD&lt;/h4&gt; &lt;h5&gt;1 – Através do Registry&lt;/h5&gt; &lt;p&gt;Acesse HKLM\System\CurrentControlSet\Services\NTDS\Parameters, localize o valor Schema Version, mude para Decimal e observe o valor.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/Trs03maneirasdeidentificarqualversodoAct_9584/clip_image002_2.jpg"&gt;&lt;img style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/Trs03maneirasdeidentificarqualversodoAct_9584/clip_image002_thumb.jpg" width="244" height="146"&gt;&lt;/a&gt;&lt;/p&gt; &lt;h5&gt;2 – Através do ADSIEDIT.MSC&lt;/h5&gt; &lt;p&gt;Instale o Support Tools (&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=96a35011-fd83-419d-939b-9a772ea2df90&amp;amp;DisplayLang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=96a35011-fd83-419d-939b-9a772ea2df90&amp;amp;DisplayLang=en&lt;/a&gt;) e execute o programa ADSIEDIT.MSC. Expanda &lt;em&gt;CN=Schema,CN=Configuration&lt;/em&gt;, e clique com o botão direito. Na Aba &lt;em&gt;Attribute Editor&lt;/em&gt;, localize atributo &lt;em&gt;ObjectVersion&lt;/em&gt; e observe o valor na coluna &lt;em&gt;Value&lt;/em&gt;.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/Trs03maneirasdeidentificarqualversodoAct_9584/clip_image004_2.jpg"&gt;&lt;img style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" border="0" alt="clip_image004" src="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/Trs03maneirasdeidentificarqualversodoAct_9584/clip_image004_thumb.jpg" width="220" height="244"&gt;&lt;/a&gt;&lt;/p&gt; &lt;h5&gt;3 – Através do utilitário C:\Windows\System32\schupgr.exe&lt;/h5&gt; &lt;p&gt;Acesse a pasta “C:\Windows\System32” de qualquer Domain Controller e simplesmente execute o programa &lt;b&gt;SCHUPGR.EXE&lt;/b&gt;. Será listado na tela o valor atual do Schema, no nosso exemplo o valor 31 na linha Current Schema Version o que significa que estamos executando um Domain Controller com o Windows Server 2003 R2.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/Trs03maneirasdeidentificarqualversodoAct_9584/clip_image006_2.jpg"&gt;&lt;img style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" border="0" alt="clip_image006" src="http://blogs.technet.com/blogfiles/technetbr/WindowsLiveWriter/Trs03maneirasdeidentificarqualversodoAct_9584/clip_image006_thumb.jpg" width="244" height="123"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;por &lt;strong&gt;&lt;em&gt;Gilson Banin&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3124731" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/technetbr/archive/tags/TechNet/default.aspx">TechNet</category><category domain="http://blogs.technet.com/technetbr/archive/tags/TechNet+Brasil/default.aspx">TechNet Brasil</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Infra-estrtutura/default.aspx">Infra-estrtutura</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Banin/default.aspx">Banin</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Dicas/default.aspx">Dicas</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Gilson+Banin/default.aspx">Gilson Banin</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Gilson/default.aspx">Gilson</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows+Server/default.aspx">Windows Server</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Windows/default.aspx">Windows</category><category domain="http://blogs.technet.com/technetbr/archive/tags/AD/default.aspx">AD</category><category domain="http://blogs.technet.com/technetbr/archive/tags/Active+Directory/default.aspx">Active Directory</category></item></channel></rss>